Command-line packet analyzer for monitoring, capturing, and filtering network traffic in real time. Supports TCP/IP protocols, pcap file export, BPF syntax, timestamped outputs, and works on UNIX-like systems with both wired and wireless interfaces.



Wireshark is described as 'Foremost network protocol analyzer with multi-platform support, deep protocol inspection, VoIP analysis, and extensive file format compatibility' and is a leading network analyzer in the network & admin category. There are more than 50 alternatives to Wireshark for a variety of platforms, including Windows, Linux, Mac, Android and iPhone apps. The best Wireshark alternative is tcpdump, which is both free and Open Source. Other great apps like Wireshark are CloudShark, NetworkMiner, Proxyman and Ettercap.
Command-line packet analyzer for monitoring, capturing, and filtering network traffic in real time. Supports TCP/IP protocols, pcap file export, BPF syntax, timestamped outputs, and works on UNIX-like systems with both wired and wireless interfaces.



Optimize packet capture workflow with CloudShark's secure, collaborative network analysis. It's ideal for IT teams and operators, available on any device. Share and solve problems faster with browser-based collaboration and centralized PCAP data management on-premise or in the cloud.
NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can extract transmitted files and certificates from PCAP files containing HTTP, FTP, SMB, SMB2, TFTP and several other protocols.




Monitor, intercept and debug HTTP/HTTPS and WebSocket traffic on macOS, iOS, Windows, and Linux. Includes advanced features such as Breakpoint, Map Local/Remote, scripting, filtering, reverse proxy, DNS spoofing, and automation for backend development.




Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks.

Real-time macOS network tool captures, displays, and filters TCP traffic using AppKit, libpcap, and Wireshark libraries, supports PCAP/PCAPNG files, offers protocol filters, drag-and-drop, noise reduction, detailed packet review, export options, and grouped traffic analysis.


Capsa performs real-time packet capturing, 24/7 network monitoring, protocol analysis, in-depth packet decoding, and automatic expert diagnosis.


PCAPdroid is an android app to capture the phone traffic and analyze it remotely (e.g. via Wireshark). The traffic can be easily downloaded from a remote device thanks to the integrated HTTP server, or streamed to a remote UDP receiver.








MicroOLAP TCPDUMP is a clone of tcpdump , the most used network sniffer/analyzer for UNIX, compiled with the original tcpdump code (http://www.tcpdump.org/), and MicroOLAP Packet Sniffer SDK.


It's open source and use CLI